AVAST keeps popping up clickered.com url malicious

I ran all the scans required and will post results below. Thanks for any help.

Please, you can use http://www.avast.com/contact-form.php for reporting potential false positive (archive or site wrong detections)
Thanks.

Lisandro,

clickered.com is a very strong indication that the system is infected with malware.

This is not a false positive.

Definitely not an FP

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-21-1554028457-1761458827-3897272916-1000\...\Run: [Best Buy pc app] => C:\Users\Todd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Best Buy\Best Buy pc app.appref-ms Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft) SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File FF Plugin: @bestbuy.com/npBestBuyPcAppDetector,version=1.0 -> C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll (Best Buy) FF Plugin-x32: @bestbuy.com/npBestBuyPcAppDetector,version=1.0 -> C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll (Best Buy) CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION R2 scores; C:\Windows\score.exe [4816384 2014-07-30] () [File not signed] 2014-09-01 11:12 - 2014-09-01 11:32 - 00000000 ____D () C:\Program Files (x86)\settings manager 2014-09-01 11:12 - 2014-09-01 11:32 - 00000000 ____D () C:\Program Files (x86)\rhv 2014-09-01 11:12 - 2014-09-01 11:32 - 00000000 ____D () C:\Program Files (x86)\arh 2014-09-01 11:12 - 2014-09-01 11:32 - 00000000 ____D () C:\Program Files (x86)\akv 2014-08-31 03:53 - 2014-08-31 03:53 - 03463520 _____ (tuneuppro.com ) C:\Users\Todd\Downloads\Unconfirmed 103500.crdownload 2014-08-31 03:50 - 2014-08-31 03:50 - 03463520 _____ (tuneuppro.com ) C:\Users\Todd\Downloads\Unconfirmed 91485.crdownload 2014-08-31 03:49 - 2014-08-31 03:49 - 03463520 _____ (tuneuppro.com ) C:\Users\Todd\Downloads\Unconfirmed 715050.crdownload 2014-08-31 02:56 - 2014-08-31 02:56 - 10117512 _____ () C:\Users\Todd\Downloads\Unconfirmed 409554.crdownload 2014-08-31 02:55 - 2014-08-31 02:55 - 10117512 _____ () C:\Users\Todd\Downloads\Unconfirmed 840180.crdownload 2014-08-31 02:55 - 2014-08-31 02:55 - 10117512 _____ () C:\Users\Todd\Downloads\Unconfirmed 124188.crdownload 2014-08-31 02:54 - 2014-08-31 02:55 - 10117512 _____ () C:\Users\Todd\Downloads\Unconfirmed 755953.crdownload 2014-08-31 02:53 - 2014-08-31 02:53 - 10117512 _____ () C:\Users\Todd\Downloads\Unconfirmed 931645.crdownload 2014-08-31 02:53 - 2014-08-31 02:53 - 10117512 _____ () C:\Users\Todd\Downloads\Unconfirmed 152622.crdownload 2014-08-30 20:13 - 2014-08-30 20:13 - 01791623 _____ () C:\Users\Todd\Downloads\Unconfirmed 380866.crdownload 2014-08-30 17:23 - 2014-08-30 17:23 - 00004590 _____ () C:\Windows\System32\Tasks\Idle~_~Crawler Runner 2014-08-30 17:23 - 2014-08-30 17:23 - 00000000 ____D () C:\Users\Todd\AppData\Local\Idle~_~Crawler 2014-08-30 17:22 - 2014-08-30 17:23 - 00000000 ____D () C:\Users\Public\35F6CCA0AADC4AC997D58E8CC3DE45A5 2014-08-17 12:31 - 2014-08-17 12:31 - 00000000 ____D () C:\Program Files (x86)\predm 2014-08-15 18:40 - 2014-08-15 18:45 - 00004242 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_60-b19.log 2014-08-15 18:39 - 2014-08-17 12:44 - 00000000 ____D () C:\Program Files (x86)\globalUpdate 2014-08-15 18:39 - 2014-08-17 08:31 - 00003246 _____ () C:\Windows\System32\Tasks\Optimizer Pro Schedule 2014-08-15 18:39 - 2014-08-15 18:39 - 00004030 _____ () C:\Windows\System32\Tasks\LaunchSignup 2014-08-15 18:39 - 2014-08-15 18:39 - 00001025 _____ () C:\Users\Todd\Desktop\PepperZip.lnk 2014-08-15 18:39 - 2014-08-15 18:39 - 00000000 ____D () C:\Users\Todd\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PepperZip 2014-08-15 18:39 - 2014-08-15 18:39 - 00000000 ____D () C:\Users\Todd\AppData\Local\globalUpdate 2014-08-15 18:39 - 2014-08-15 18:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PepperZip 2014-08-15 18:39 - 2014-08-15 18:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2 2014-08-15 18:39 - 2014-08-15 18:39 - 00000000 ____D () C:\Program Files (x86)\PepperZip 2014-08-15 18:38 - 2014-07-30 14:45 - 04816384 _____ () C:\Windows\score.exe 2014-08-11 14:52 - 2014-08-11 14:52 - 00000000 ____D () C:\Users\Todd\AppData\Local\{BB1B5C11-4B43-431C-9564-5FD979ED89E5} 2014-08-10 11:09 - 2014-08-10 11:09 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2014-09-01 11:32 - 2013-12-17 14:14 - 00000000 ____D () C:\Users\Todd\AppData\Local\NativeMessaging 2014-09-01 11:32 - 2013-12-17 14:14 - 00000000 ____D () C:\Users\Todd\AppData\Local\CRE 2014-09-01 11:32 - 2013-12-17 14:14 - 00000000 ____D () C:\ProgramData\Conduit 2014-09-01 11:32 - 2009-07-13 22:20 - 00000000 ____D () C:\Windows\Branding Task: {22025DCA-C6BD-4465-A989-22DE7AAEAA36} - System32\Tasks\Idle~_~Crawler Runner => %LOCALAPPDATA%\Idle~_~Crawler\Idle~_~Crawler.exe <==== ATTENTION Task: {68EA78BD-EC8F-4AF8-BC4A-E5D6C77A5DA9} - System32\Tasks\Microsoft\Windows\Maintenance\Idle~_~Crawler Update => %LOCALAPPDATA%\Idle~_~Crawler\Idle~_~Crawler.exe <==== ATTENTION Task: {90DD16B3-D8B6-4221-BEC5-4DF182D9252C} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe <==== ATTENTION Task: {D3C07477-83D2-4F9C-BD4A-C201B92DF386} - System32\Tasks\Optimizer Pro Schedule => C:\Program Files (x86)\Optimizer Pro\OptProLauncher.exe <==== ATTENTION C:\Program Files (x86)\MyPC Backup EmptyTemp: CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.

[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S1].txt as well.

:slight_smile:

Here are the two additional logs that you requested. Doesn’t seem like I am getting anymore avast warnings!

whenever i open internet explorer, every couple of minutes, avast will pop up saying its blocked a malicious

Hi abigail.abby73,

Welcome to the forums.

Please start your own topic using this link: https://forum.avast.com/index.php?action=post;board=4.0

@tuscani03

Subject to no further problems :slight_smile:

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :thumbsup:

A good workman always cleans up after himself so…The following will implement some cleanup procedures as well as reset System Restore points:
Download and run Delfix

https://dl.dropboxusercontent.com/u/73555776/delfix.JPG

: Keep Java Updated :

WARNING: Java is the #1 exploited program at this time. The Department of Homeland Security recommends that computer users disable Java
See this article

I would recommend that you completely uninstall Java unless you need it to run an important software.
In that instance I would recommend that you disable Java in your browsers until you need it for that software and then enable it. (See How to diasble Java in your web browser and How to unplug Java from the browser)

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

CryptoPrevent install this programme to lock down and prevent crypto ransome ware

https://dl.dropboxusercontent.com/u/73555776/CryptoPrevent.JPG

Malwarebytes.

Update and run weekly to keep your system clean

It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To learn more about how to protect yourself while on the internet read this little guide Best security practices Keep safe :wave:

Thank you very much!! I will check back in a few days. ;D